CLAIMS 

1- A method of managing cookies in a data processing system (1) comprising 
a user agent (100) requesting a resource associated with a cookie from a 
content provider (200), said method comprising the step of said user agent 
(100) transmitting, in response to reception of a privacy policy associated with 
said cookie, a cookie-policy receipt to said content provider (200), said cookie- 
policy receipt specifying whether a user associated with said user agent (100) 
accepts that said content provider (200) provides said cookie to user 
equipment (300) associated with said user agent (200). 

2. The method according to claim 1, further comprising the step of including 
said cookie-policy receipt in a resource fetch message transmitted from said 
user agent (100) to said content provider (200). 

3. The method according to claim 1 or 2, further comprising the steps of: 

said user agent (100) comparing said received privacy policy with 
user preference, said user preference specifying a cookie privacy policy 
accepted by said user; and 

said user agent (100) generating said cookie-policy receipt based on 
said comparison. 

4. The method according to claim 3, wherein, if said received privacy policy 
does not fulfill said user preference, said method comprising the steps of: 

said user agent (100) presenting said received privacy policy for said 
user on said user equipment (300); and 

said user agent (100) generating, in response to a user-input signal, 
said cookie-policy receipt. 

5. The method according to claim 1 or 2, further comprising the steps of: 

said user agent (100) presenting said received privacy policy for said 
user on said user equipment (300); and 

said user agent (100) generating, in response to a user-input signal, 
said cookie-policy receipt. 



AMENDED SHEET 



frCT l^r.,u::nnai Application J PCT/SE2003/001067 

- - 30 16-06-2004 

6. The method according to any of the claims 1 to 5, further comprising the 
step of authenticating said cookie-policy receipt with an authentication key 
(135; 355) associated with said user agent (100). 

7. The method according to any of the claims 1 to 6, wherein, if said cookie- 
policy receipt is specifying that said user does not accept that said content 
provider (200) provides said cookie to said user equipment (300), said method 
comprising the step of removing a stored cookie associated with said 
requested resource from a storage (330) in said user equipment (300). 

8. The method according to any of the claims 1 to 6, wherein, if said cookie- 
policy receipt is specifying that said user does not accept that said content 

- provider (200) provides said cookie to said user equipment (300), said method 
comprising the step of ignoring a cookie request command transmitted from 
said content provider (200) to said user agent (100). 

9. A method of providing cookies in a data processing system (1) comprising 
a user agent (100) requesting a resource associated with a cookie from a 
content provider (200), said method comprising the steps of: 

transmitting a privacy policy associated with said cookie to said user 
agent (100); and 

said content provider (200) providing, in response to reception of a 
cookie-policy receipt from said user agent (100), said cookie to user equipment 
(300) associated with said user agent (100) if said cookie-policy receipt is 
specifying that a user associated with said user agent (100) accepts that said 
content provider (200) provides said cookie to said user equipment (300). 

10. The method according to claim 9, wherein said cookie-policy receipt is 
received in a resource fetch message transmitted from said user agent (100). 

11. The method according to claim 9 or 10, wherein, if said cookie-policy 
receipt is specifying that said user accepts that said content provider (200) 
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provides said cookie to said user equipment (300), said method comprising the 
step of providing said cookie-associated resource. 

12. The method according to any of the claims 9 to 11, wherein said cookie- 
policy receipt is generated based on a comparison between said received 
privacy policy and user preference that specifies a cookie privacy policy 
accepted by said user. 

13. A user agent (100) provided in a data processing system (1) for requesting 
a resource associated with a cookie from a content provider (200), said user 
agent (100) comprising means for transmitting (110), in response to reception 
of a privacy policy associated with said cookie, a cookie-policy receipt to said 
content provider (200), said cookie-policy receipt specifying whether a user 
associated with said user agent (100) accepts that said content provider (200) 
provides said cookie to user equipment (300) associated with said user agent 
(100). 

14. The user agent according to claim 13, wherein said transmitting means 
(110) being adapted for including said cookie-policy receipt in a resource fetch 
message transmitted to said content provider (200). 

15. The user agent according to claim 13 or 14, further comprising: 

. - means for comparing (160) said received privacy policy with user 
preference, said user preference specifying a cookie privacy policy accepted by 
said user; and 

means for generating (125), connected to said comparing means 
(160), said cookie-policy receipt based on said comparison. 

16. The user agent according to claim 15, further comprising means for 
presenting (110) said received privacy policy for said user on said user 
equipment (300) if said privacy policy does not fulfill said user preference, said 
generating means (125) being adapted for generating said cookie-policy receipt 
in response to a user input signal. 
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17. The user agent according to claim 13 or 14, further comprising: 

means for presenting (1 10) said received privacy policy for said user 
on said user equipment (300); and 

means for generating (125) said cookie-policy receipt in response to 
a user input signal. 

18. The user agent according to any of the claims claim 13 to 17, further 
comprising means for authenticating (130) said cookie-policy receipt with an 
authentication key (135; 355) associated with said user agent (100). 

19. The user agent according to any of the claims 13 to 18, further 
comprising means for removing (140) a stored cookie associated with said 
requested resource from a storage (330) in said user equipment (300) if said 
cookie-policy receipt is specifying that said user does not accept that said 
content provider (200) provides said cookie to said user equipment (300). 

20. A content provider (200) adapted for providing a requested resource 
associated with a cookie to a user agent (100) in a data processing system (1), 
said content provider (200) comprises: 

means for transmitting (2 10), in response to a resource request from 
said user agent (100), a privacy policy associated with said cookie to said user 
agent (100); and 

means for providing (230), in response to a cookie-policy receipt 
transmitted from said user agent (100), said cookie to user equipment (300) 
associated with said user agent (100), said cookie providing means (230) being 
adapted for providing said cookie if said cookie-policy receipt is specifying that 
a user associated with said user agent (100) accepts that said content provider 
(200) provides said cookie to said user equipment (300). 

21. The content provider according to claim 20, wherein said cookie-policy 
receipt is received in a resource fetch message transmitted from said user 
agent (100). 
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22. The content provider according to claim 20 or 21, further comprising 
means for providing (240) said cookie-associated resource if said cookie-policy 
receipt is specifying that said user accepts that said content provider (200) 

5 provides said cookie to said user equipment (300). 

23. The content provider according to any of the claims 20 to 22, wherein 
said cookie-policy receipt is generated based on a comparison between said 
received privacy policy and user preference that specifies a cookie privacy 

10 policy accepted by said user. 



24. A system for managing cookies in a data processing system (1) 
comprising a user agent (100) requesting a resource associated with a cookie 
from a content provider (200), said system comprising: 

means for providing (240) a privacy policy associated with said 

cookie; 

means for transmitting (110) a cookie-policy receipt, said receipt 
transmitting means (1 10) being responsive to said privacy policy; and 

means for providing (230) said cookie in response to said cookie- 
policy receipt specifying that a user associated with said user agent (100) 
accepts that said content provider provides (200) said cookie to user 
equipment (300) associated with said user agent (100). 
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